HackerOne°ä²¼µÚËĽìÄê¶ÈHACKER-POWERED°²È«»ã±¨£»£»£»£»£»£»£»£»ÐµÄË®¿Ó¹¥»÷»î¶¯Earth KitsuneÕë¶Ôº«¹úÍâÇÈ

°ä²¼¹¦·ò 2020-11-02

1.HackerOne°ä²¼µÚËĽìÄê¶ÈHACKER-POWERED°²È«»ã±¨


1.png


HackerOne°ä²¼µÚËĽìÄê¶ÈHACKER-POWERED°²È«»ã±¨£¬£¬£¬£¬£¬³Æ¿çÕ¾µã¾ç±¾£¨XSS£©ÊÇ×î³£¼ûµÄ·ì϶ÀàÐÍ£¬£¬£¬£¬£¬±È2019ÄêÔö³¤ÁË134%¡£¡£¡£¡£¡£¡£¡£¡£»ã±¨ÏÔʾ£¬£¬£¬£¬£¬XSS·ì϶ռÁ˻㱨µÄËùÓзì϶µÄ18%£¬£¬£¬£¬£¬×ܼƻñµÃÁË420ÍòÃÀÔªµÄ½±½ð(±ÈÈ¥ÄêÔö³¤ÁË26%)¡£¡£¡£¡£¡£¡£¡£¡£´Ë±í£¬£¬£¬£¬£¬²»µ±½Ó¼û½ÚÔì·ì϶Ëù»ñµÃµÄ½±½ð¶î¶È±ÈÈ¥Äêͬ±ÈÔö³¤134£¥£¬£¬£¬£¬£¬¸ß´ïµ½400ÍòÃÀÔª£¬£¬£¬£¬£¬Æä´ÎÊÇÐÅÏ¢Åû¶·ì϶£¬£¬£¬£¬£¬Í¬±ÈÔö³¤63£¥¡£¡£¡£¡£¡£¡£¡£¡£ÕâÁ½ÖÖ·½Ê½³ÇÊÐй¶DZÔÚµÄÃô¸ÐÊý¾Ý£¬£¬£¬£¬£¬ÀýÈçÓ×ÎÒÉí·ÝÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

hackerone.com/hacker-powered-security-report


2.×êÑÐÈËÔ±³ÆÈÔÓг¬¹ý10ÍòÌ¨ÍÆËã»úÒ×ÊÜSMBGhost¹¥»÷


2.jpg


×êÑÐÈËÔ±Jan Kopriva³ÆÈÔÓг¬¹ý10ÍòÌ¨ÍÆËã»úÒ×ÊÜSMBGhost¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£SMBGhost·ì϶£¨CVE-2020-0796£©ÎªMicrosoft·þÎñÆ÷ÐÂÎſ飨SMB£©ºÍ̸ÖеÄÒ»¸öÔ¶³ÌÖ´ÐдúÂë·ì϶£¬£¬£¬£¬£¬ÀûÓø÷ì϶¿É½øÐÐÈ䳿¹¥»÷£¬£¬£¬£¬£¬ÒÔ´«²¼µ½ÆäËûÍÆËã»úÉÏ£¬£¬£¬£¬£¬MicrosoftÒÑÔÚÈýÔ·ݽ¨¸´¸ÃÎÊÌâ¡£¡£¡£¡£¡£¡£¡£¡£Jan Kopriva·¢ÏÖÈÔÓг¬¹ý103000Ì¨ÍÆËã»úÒ×ÊÜ´ËÀ๥»÷£¬£¬£¬£¬£¬ÆäÖдóÎÞÊýλÓŲ́Í壨22£¥£©£¬£¬£¬£¬£¬Æä´ÎÊÇÈÕ±¾£¨20£¥£©ºÍ¶íÂÞ˹£¨11£¥£©¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110247/hacking/smbghost-vulnerable-machines-dangers.html


3.еÄË®¿Ó¹¥»÷»î¶¯Earth KitsuneÕë¶Ôº«¹úÍâÇÈ


3.jpg


Ç÷Ïò¿Æ¼¼µÄ×êÑÐÈËÔ±Åû¶ÁËеÄË®¿Ó¹¥»÷»î¶¯Earth Kitsune£¬£¬£¬£¬£¬ÖØÒªÕë¶Ôº«¹úÍâÇÈ¡£¡£¡£¡£¡£¡£¡£¡£×êÑÐÈËÔ±·¢ÏÖ¹¥»÷²úÉúÔÚ3Ô¡¢5ÔºÍ9Ô£¬£¬£¬£¬£¬ºÚ¿ÍʹÓÃÁ˶ñÒâÈí¼þSLUB(¼´SLackºÍgithUB)ºÍÁ½¸öкóÃÅ£¬£¬£¬£¬£¬dneSpyºÍagfSpy£¬£¬£¬£¬£¬Ö¼ÔÚÊÕÊÜÊÜϰȾµÄϵͳ²¢´ÓÖÐÇÔÈ¡Êý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£ÓëÆäËû¹¥»÷·ÖÆçµÄÊÇ£¬£¬£¬£¬£¬ËüÔÚÊܺ¦»úеÉϲ¿ÊðÁË´óÁ¿µÄÑù±¾£¬£¬£¬£¬£¬Ê¹ÓÃÁ˶à¸öºÅÁîºÍ½ÚÔì(C&C)·þÎñÆ÷£¬£¬£¬£¬£¬»¹ÀûÓÃÁË4¸öN-day·ì϶¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110192/apt/operation-earth-kitsune.html


4.FireEye·¢ÏÖEmotetÒÔÍòÊ¥½ÚÔ¼ÇëΪÖ÷Ìâ½øÐд«²¼


4.jpg


FireEye×êÑÐÈËÔ±Alex Lanstein·¢ÏÖEmotetÒÔÍòÊ¥½ÚÔ¼ÇëΪÖ÷Ìâ½øÐд«²¼¡£¡£¡£¡£¡£¡£¡£¡£ºÚ¿ÍÒÔ2020ÍòÊ¥½ÚΪÖ÷Ì⣬£¬£¬£¬£¬»Ñ³ÆÔ¼ÇëÊܺ¦Õß²ÎÓëÍòÊ¥½ÚÅɶÔ£¬£¬£¬£¬£¬²¢°µÊ¾ËùÓоßÌåÐÅÏ¢¶¼ÔÚ¸½¼þÖУ¬£¬£¬£¬£¬ÒÔÓÕʹÓû§´ò¿ª¶ñÒ⸽¼þ¡£¡£¡£¡£¡£¡£¡£¡£Ò»µ©Óû§´ò¿ª¸½¼þ£¬£¬£¬£¬£¬¾Í»á±»ÒªÇóµã»÷ÆôÓñà×ëºÍÆôÓÃÄÚÈݰ´Å¥£¬£¬£¬£¬£¬Ö¼ÔÚ×°ÖÃEmotet Trojan¡£¡£¡£¡£¡£¡£¡£¡£³É¹¦×°ÖöñÒâÈí¼þºó£¬£¬£¬£¬£¬Emotet½«ÀûÓøÃÍÆËã»ú·¢ËÍÀ¬»øÓʼþ£¬£¬£¬£¬£¬²¢ÌáÒéÀÕË÷Èí¼þ¹¥»÷¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/emotet-malware-wants-to-invite-you-to-a-halloween-party/


5.ÓÎÏ·¹«Ë¾Gaming PartnersϰȾREvilµ¼Ö²¿ÃÅÊý¾Ýй¶


5.jpg


ÓÎÏ·¹«Ë¾Gaming PartnersϰȾREvil£¬£¬£¬£¬£¬²¢µ¼Ö²¿ÃÅÊý¾Ýй¶¡£¡£¡£¡£¡£¡£¡£¡£Gaming Partners International£¨GPI£©ÊÇÒ»¼ÒΪȫÇò¶Ä³¡Ìṩ²©²Ê¼Ò¾ßºÍÉ豸µÄÈ«·½Î»·þÎñ¹©¸øÉÌ¡£¡£¡£¡£¡£¡£¡£¡£REvilÍÅ»ïÐû³ÆÆäÒѼÓÃܸù«Ë¾ÏµÍ³£¬£¬£¬£¬£¬²¢ÇÔÈ¡ÁË540GbµÄ¼¼ÊõºÍ½ðÈÚÎļþ¡£¡£¡£¡£¡£¡£¡£¡£Ð¹Â¶Êý¾ÝÔ̺¬¹«Ë¾³ÁÒªÐÅÏ¢¡¢¼¼·¨Êõ¾Ý¡¢²ÆÕþÎļþ¡¢ÓëÀ­Ë¹Î¬¼Ó˹¡¢°ÄÃÅ¡¢Å·ÖÞËùÓжij¡µÄºÏͬ¡¢ÒøÐÐÎļþµÈ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÍŻﻹ½«Ð¹Â¶Êý¾ÝµÄ½ØÍ¼¹«¿ªÔÚÆäÊý¾Ýй¶վµã£¬£¬£¬£¬£¬²¢°µÊ¾¹«Ë¾72Ó×ʱÄÚ²»Ö§¸¶Êê½ð£¬£¬£¬£¬£¬ËûÃǽ«¹«¿ªËùÓб»µÁÊý¾Ý¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://securityaffairs.co/wordpress/110237/cyber-crime/gaming-partners-international-revil-ransomware.html


6.ºÚ¿ÍÔÚ°µÍøÏúÊÛ´Ó17¼Ò¹«Ë¾ÇÔÈ¡µÄ3400ÍòÌõÓû§¼Í¼


6.png


10ÔÂ28ÈÕ£¬£¬£¬£¬£¬ºÚ¿ÍÔÚ°µÍøÏúÊÛ´Ó17¼Ò¹«Ë¾ÇÔÈ¡µÄ3400ÍòÌõÓû§¼Í¼¡£¡£¡£¡£¡£¡£¡£¡£Æ¾¾Ýй¶Êý¾ÝÏÔʾ£¬£¬£¬£¬£¬ËùÓб»ÏúÊÛµÄÊý¾Ý¿â¶¼ÊÇÔÚ2020Äê±»µÁµÄ£¬£¬£¬£¬£¬ÆäÖÐй¶×î¶àµÄÊÇGeekie.com.br£¬£¬£¬£¬£¬ÓÐ810ÍòÌõ£¬£¬£¬£¬£¬¶øÊÜÓ°Ïì×î´óµÄÊÇÐÂ¼ÓÆÂµÄRedMart¡£¡£¡£¡£¡£¡£¡£¡£Õâ´ÎÊÜÓ°ÏìµÄ17¼Ò¹«Ë¾±ðÀëΪGeekie.com.br£¨810Íò£©¡¢Clip.mx£¨470Íò£©¡¢Wongnai.com£¨430Íò£©¡¢Cermati.com£¨290Íò£©¡¢Everything5pounds.com£¨290Íò£©¡¢Eatigo.com£¨280Íò£©¡¢Katapult.com£¨220Íò£©¡¢Wedmegood.com£¨130Íò£©¡¢RedMart£¨110Íò£©¡¢Coupontools.com£¨100Íò£©¡¢W3layouts.com£¨78.9Íò£©¡¢Game24h.vn£¨77.9Íò£©¡¢Invideo.io£¨57.1Íò£©ºÍApps-builder.com£¨38.6£©¡£¡£¡£¡£¡£¡£¡£¡£


Ô­ÎÄÁ´½Ó£º

https://www.bleepingcomputer.com/news/security/hacker-is-selling-34-million-user-records-stolen-from-17-companies/